Watch: How Hackers Helped the DOJ Protect Security Researchers
Leonard Bailey's BSidesLV 2026 keynote tells the inside story of the DOJ's good-faith security research policy, and how the hacker community helped make it happen. Watch it here.
Every once in a while a talk comes along that captures a piece of hacker history from the inside. Leonard Bailey's keynote at BSides Las Vegas 2026 is one of those talks.
Bailey is the former Head of the Cybersecurity Unit and Special Counsel for National Security in the Criminal Division of the US Department of Justice. For years, he was the person on the other side of the table when the security research community came to talk about the Computer Fraud and Abuse Act (CFAA). His Breaking Ground keynote, "Patching the Law: The Story of How Hackers Helped DOJ Protect Security Researchers," is exactly what the title promises: a first-person account of how good-faith hackers and federal prosecutors went from mutual suspicion to genuine partnership, told by the official who lived it.
Leonard Bailey, "Patching the Law", BSides Las Vegas 2026 (video starts at his talk)
The player above is cued to the start of Leonard's talk, 1:49:16 into the BSidesLV Breaking Ground stream. If it doesn't start there for you, jump straight in with this link. The prepared talk runs about 30 minutes, followed by a Q&A that is well worth staying for.
Why this one matters
The centerpiece of the story is the Department of Justice's 2022 revision of its CFAA charging policy: the first time the Department directed that good-faith security research should not be charged. Bailey retells the announcement in the talk: "The department has never been interested in prosecuting good faith computer security research as a crime."
That sentence did not appear out of nowhere, and Bailey tells the story of how it came to exist, deliberately, in three acts. Act one is world-building, and it opens in a dark place: 2012, and the felony CFAA prosecution of Aaron Swartz. It traces the first real contact between researchers and prosecutors, and ends with what Bailey calls a kumbaya moment: a feel-good meeting where people felt heard, but nothing had actually changed. Act two is the unglamorous middle where the work lives: weekly phone calls that ran for months, hard questions about where legitimate research ends and criminal conduct begins, and incremental wins like the renewal of the DMCA security research exemption. Act three brings the crisis, the climax, and the payoff: the 2022 charging policy. As Bailey puts it, borrowing a line often attributed to JFK: success has many parents, and this one had many, many parents.
For everyone working on vulnerability disclosure and safe harbor, this is required viewing. It is the clearest insider account we have of how legal reform actually happens: not through one lawsuit or one hearing, but through sustained good-faith engagement. And it is, not incidentally, the story disclose.io exists to continue. Bailey's closing call to action names I Am The Cavalry, Hackers on the Hill, UnDisruptable27, and disclose.io as places to plug in.
The Q&A is a talk of its own
Stay past the applause. The questions range from safe harbor and cold-shouldered disclosures to the one everyone in security is starting to ask: what happens to good faith when an AI agent is doing the work? One questioner put it directly: the law has leaned on the good faith of an individual researcher, but now an agent may be doing some of the work, and it may drift from the original intent of the human who launched it. Where are the seams in the law?
Bailey's answer is worth the price of admission. Before retiring from the Department he looked at how the CFAA applies to security research on AI models, and his verdict is that it is genuinely unsettled: is a jailbreak prompt "accessing a computer without authorization" when the computer is there to take commands from you? But agentic, he argues, does not mean unaccountable. There was a prompt somewhere. Someone knows how the model behaves when asked. Accountability can attach when you keep doing that thing. Courts are only beginning to weigh in, and he points to a recent case involving agentic scraping as an early signal of how they might.
And one moment from the Q&A stuck with just about everyone:
“I didn’t expect to be welcomed into this community in the way that I was” - Leonard Bailey, Fmr DoJ
- cje (@caseyjohnellis) August 3, 2026
there’s soooooo much in that one statement ❤️ pic.twitter.com/O1qoLNofOv
Where to jump in
- 1:49:29 - the talk begins
- 1:51:01 - act one: the dark years, starting with the Aaron Swartz prosecution
- 2:02:00 - act two: weekly calls, hard questions, the DMCA exemption
- 2:11:41 - act three: crisis, climax, and the 2022 charging policy
- 2:20:01 - end of the prepared talk, start of Q&A
- 2:24:37 - safe harbor and the private-sector side of the equation
- 2:29:03 - the question about AI agents, liability, and the seams in the CFAA
- 2:36:08 - closing
If this talk moves you the way it moved the room, the takeaway is simple: the door between the hacker community and government is open, and walking through it works. Start with a safe harbor policy for your own organization, explore disclose.io, and keep showing up.